CVE-2011-1660
Multiple cross-site scripting (XSS) vulnerabilities in the DataDynamics.Reports.Web class library in GrapeCity Data Dynamics Reports before 1.6.2084.14 allow remote attackers to inject arbitrary web script or HTML via (1) the reportName or (2) uniqueId…
Does this matter?
Lower severity and a low EPSS score (1.33%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple cross-site scripting (XSS) vulnerabilities in the DataDynamics.Reports.Web class library in GrapeCity Data Dynamics Reports before 1.6.2084.14 allow remote attackers to inject arbitrary web script or HTML via (1) the reportName or (2) uniqueId parameter to CoreViewerInit.js, or the (3) uniqueId or (4) traceLevel parameter to CoreController.js, as reachable by CoreHandler.ashx.
- CVSS 2.0
- 4.3 MEDIUMAV:N/AC:M/Au:N/C:N/I:P/A:N
- EPSS
- 1.33% probability · 69th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-79
- Affected
- grapecity/data dynamics reports
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/43953Vendor Advisory
- http://securityreason.com/securityalert/8190
- http://www.gcpowertools.com/DownloadLatestVersionPatch
- http://www.osvdb.org/71488
- http://www.securityfocus.com/archive/1/517244/100/0/threaded
- http://www.securityfocus.com/bid/47015Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66545
- http://secunia.com/advisories/43953Vendor Advisory
- http://securityreason.com/securityalert/8190
- http://www.gcpowertools.com/DownloadLatestVersionPatch
- http://www.osvdb.org/71488
- http://www.securityfocus.com/archive/1/517244/100/0/threaded
- http://www.securityfocus.com/bid/47015Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/66545
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.